CVE-2026-101111 - Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6
CVE ID :CVE-2026-101111
Published : Sept. 28, 2026, 6:48 p.m. | 24 minutes ago
Description :Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo $_REQUEST["title"];). A value containing a double quote closes the attribute early and allows arbitrary HTML/JavaScript to follow.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 28, 2026, 6:48 p.m. | 24 minutes ago
Description :Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo $_REQUEST["title"];). A value containing a double quote closes the attribute early and allows arbitrary HTML/JavaScript to follow.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...